Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2021-31819 In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each… Halibut 4.4.7+ Fix from $2,3002021-09-22 CRITICAL 9.8 CVE-2021-39392 The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the … Mylittlebackup after 1.7 Fix from $2,3002021-09-15 CRITICAL 10.0 CVE-2021-37181 A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus… Cerberus Dms Patch available Fix from $2,3002021-09-14 HIGH 8.8 CVE-2021-39207 parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is v… Parlai 1.1.0+ Fix from $1,9502021-09-10 CRITICAL 9.8 CVE-2021-24040EPSS 17% Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input,… Parlai 1.1.0+ Fix from $2,3002021-09-10 CRITICAL 9.8 CVE-2021-37579EPSS 7% The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.… Dubbo 2.7.13 / 3.0.2+ Fix from $2,3002021-09-09 HIGH 8.1 CVE-2021-32836 ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserializat… Zstack 3.10.12 / 4.1.6+ Fix from $1,9502021-09-09 HIGH 8.8 CVE-2021-35217EPSS 73% Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and r… Patch Manager after 2020.2.5 Fix from $1,9502021-09-08 CRITICAL 9.8 CVE-2021-36163 In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque… Dubbo after 3.0.1 Fix from $2,3002021-09-07 HIGH 7.8 CVE-2021-32568 mrdoc is vulnerable to Deserialization of Untrusted Data Mrdoc after 0.7.0 Fix from $1,9502021-09-06 HIGH 8.8 CVE-2021-35215EPSS 70% Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit … Orion Platform after 2020.2.5 Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-35216EPSS 81% Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An … Patch Manager 2020.2.6+ Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-35218EPSS 76% Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network acces… Orion Platform 2020.2.6+ Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-36231 Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating syste… Mik.starlight No fix yet Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-21677 Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from dis… Code Coverage Api after 1.4.0 Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-36981EPSS 6% In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code. Verinice 1.22.2+ Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-39132 Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an autho… Rundeck 3.3.14 / 3.4.3+ Fix from $1,9502021-08-30 CRITICAL 9.8 CVE-2021-34066 An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to exe… Developer Be 1.0+ Fix from $2,3002021-08-30 CRITICAL 9.8 CVE-2021-21741 There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit… Zxv10 M910 Firmware Mitigation only Fix from $2,3002021-08-30 HIGH 8.8 CVE-2021-24579EPSS 8% The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any v… Bold Page Builder 3.1.6+ Fix from $1,9502021-08-30 HIGH 7.8 CVE-2021-21869 An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development … Codesys Patch available Fix from $1,9502021-08-25 HIGH 7.5 CVE-2021-31010 KEV A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and… Ipados 7.6.2 / 10.15.7+ Fix from $1,9502021-08-24 HIGH 8.5 CVE-2021-39152EPSS 11% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39150 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques… Fedora 1.4.18+ Fix from $1,9502021-08-23 MEDIUM 6.3 CVE-2021-39140EPSS 6% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca… Debian Linux 1.4.18+ Fix from $1,6002021-08-23 HIGH 8.5 CVE-2021-39153 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39154 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39141EPSS 16% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39144 KEVEPSS 98% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39145 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23